Vulnerability Name: | CVE-2022-0485 (CCN-235010) | ||||||||||||||||||
Assigned: | 2022-01-27 | ||||||||||||||||||
Published: | 2022-01-27 | ||||||||||||||||||
Updated: | 2022-12-01 | ||||||||||||||||||
Summary: | A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image. | ||||||||||||||||||
CVSS v3 Severity: | 4.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N) 4.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
4.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
4.2 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||
Vulnerability Type: | CWE-252 | ||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-0485 Source: secalert@redhat.com Type: Vendor Advisory secalert@redhat.com Source: CCN Type: Red Hat Bugzilla - Bug 2046194 CVE-2022-0485 libnbd: nbdcopy ignore read and write errors - destination image corrupted Source: secalert@redhat.com Type: Exploit, Issue Tracking, Vendor Advisory secalert@redhat.com Source: secalert@redhat.com Type: Issue Tracking, Vendor Advisory secalert@redhat.com Source: XF Type: UNKNOWN libnbd-cve20220485-sec-bypass(235010) Source: secalert@redhat.com Type: Patch, Third Party Advisory secalert@redhat.com Source: CCN Type: libnbd GIT Repository maint: Security announcement for CVE-2022-0485 Source: secalert@redhat.com Type: Patch, Vendor Advisory secalert@redhat.com Source: CCN Type: Mend Vulnerability Database CVE-2022-0485 | ||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1:![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |